Skip navigation

DSpace

機構典藏 DSpace 系統致力於保存各式數位資料(如:文字、圖片、PDF)並使其易於取用。

點此認識 DSpace
DSpace logo
English
中文
  • 瀏覽論文
    • 校院系所
    • 出版年
    • 作者
    • 標題
    • 關鍵字
    • 指導教授
  • 搜尋 TDR
  • 授權 Q&A
    • 我的頁面
    • 接受 E-mail 通知
    • 編輯個人資料
  1. NTU Theses and Dissertations Repository
  2. 電機資訊學院
  3. 電機工程學系
請用此 Handle URI 來引用此文件: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/97966
標題: 可信執行環境保護的組合型隨機數產生器於無人機之應用
Combinatorial Random Number Generators Protected by Trusted Execution Environments for Drone Applications
作者: 王思翰
Szu-Han Wang
指導教授: 吳沛遠
Pei-Yuan Wu
共同指導教授: 賴怡吉
Alexander I-Chi Lai
關鍵字: 隨機數產生器,熵源組合,可信任執行環境,無人機,
Random Number Generators,Entropy Source Combination,Trusted Execution Environment,Drones / Unmanned Aerial Vehicle (UAV),
出版年 : 2025
學位: 碩士
摘要: 在現代資安架構中,隨機數產生器(Random Number Generator, RNG)的可靠性對於保護加密運算及提升系統對抗網路威脅的能力具有關鍵性影響。傳統設計普遍依賴單一熵源,當系統部分遭受攻擊時,尤其是在一般執行環境容易被外部攻擊的情境下,隨機數品質易受影響,進而削弱整體系統安全性。

本論文提出一套結合可信任執行環境(Trusted Execution Environment, TEE)與豐富執行環境(Rich Execution Environment, REE) 的組合型隨機數生成框架。此架構於 TEE 與 REE 中分別部署獨立的 RNG,並設計多種混合機制來融合兩個來源之隨機數。藉由跨域熵源混合與冗餘保護設計,即使其中一個熵源遭受破壞,最終隨機數輸出仍可保持高不可預測性,同時透過 TEE 的硬體隔離特性,進一步鞏固整體系統的安全韌性。

本研究使用 NIST SP800-22 隨機性測試套件進行評估,結果顯示所提出之組合型 RNG 在隨機性品質上能維持或優於單一熵源。為驗證其實務應用性,本架構亦整合至無人載具(Unmanned Aerial Vehicle, UAV)系統環境中,展示其於資源受限邊緣設備中提升隨機數安全性的效果。
Random number generators (RNGs) play a crucial role in cryptographic operations to establish cybersecurity defense. Traditional designs of RNGs, however, typically rely on a single entropy source, causing critical vulnerabilities to the overall system security.

To address the aforementioned challenge, this study proposes a combinatorial RNG scheme protected by a hybrid architecture combining a hardware-protected Trusted Execution Environment (TEE) and the conventional Rich Execution Environment (REE). In this framework, Independent RNGs are separately deployed in the TEE and REE domains, respectively, where their outputs are combined securely in TEE through selected techniques, including XOR operations, SHA-256 hashing, AES encryption, or chaining mechanisms. The hardware isolation enforced by TEE further protects the critical entropy sources as well as the combinatorial operation. By leveraging cross-domain entropy mixture and redundancy, the framework ensures that even if some entropy source is compromised, the final output remains adequately random. A benefit of such a framework is that some entropy sources can be placed outside TEE to save the critical security resources, without compromising the overall security level.

Extensive evaluations using the NIST SP800-22 randomness test suite verified that the proposed combinatorial RNG improves randomness quality compared to single-source RNGs. Moreover, the proposed approach was realized on a companion computer prototype for an unmanned aerial vehicle (UAV) to validate practical applicability, showcasing its potential to enhance randomness security in resource-constrained edge devices.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/97966
DOI: 10.6342/NTU202501452
全文授權: 同意授權(全球公開)
電子全文公開日期: 2025-07-24
顯示於系所單位:電機工程學系

文件中的檔案:
檔案 大小格式 
ntu-113-2.pdf1.78 MBAdobe PDF檢視/開啟
顯示文件完整紀錄


系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved